Reporting a vulnerability
Please email contact@booleanarray.com with the details. If a report is sensitive, mention that you'd like to arrange an encrypted channel and we'll follow up. Our machine-readable contact details are published at /.well-known/security.txt.
What to include
- A clear description of the issue and its potential impact.
- Step-by-step instructions to reproduce it (proof-of-concept if possible).
- The affected URL, product, or component and any relevant configuration.
- Your name or handle, if you'd like to be credited.
Our commitment
- We'll acknowledge your report within 3 business days.
- We'll keep you informed as we investigate and work toward a fix.
- We'll credit you for the discovery if you'd like (and consent to it).
Safe harbor
We consider security research and vulnerability disclosure conducted in good faith and in accordance with this policy to be authorized. We will not pursue legal action against you for such research, provided you make a genuine effort to avoid privacy violations, data destruction, and service disruption, and you give us reasonable time to remediate before any public disclosure.
Please do
- Report any vulnerability you discover promptly.
- Give us a reasonable window to fix an issue before disclosing it publicly.
- Only interact with accounts you own or have explicit permission to test.
Please don't
- Access, modify, or delete data that isn't yours.
- Run attacks that could degrade or disrupt our services (e.g. DoS, spam).
- Use social engineering, phishing, or physical attacks against our people.
- Publicly disclose a vulnerability before we've had a chance to address it.
Scope
This policy covers Boolean Array's website and the products we build and operate. Third-party services we rely on are governed by their own disclosure programs.
Thank you for helping keep Boolean Array and our users safe.